nix: openFirewall defaults false across forge/gateway/matrix (#651)
mara on #651: "Dont default openFirewall to true." Flip the `openFirewall` default from `true` to `false` for all three modules that expose host-side ports: - `services.hyperhive.forge.openFirewall` (httpPort 3000 + sshPort 2222) - `services.hyperhive.gateway.openFirewall` (port 80) - `services.hyperhive.matrix.openFirewall` (httpPort 8008) Rationale: secure-by-default. With shared host netns, the host + every agent container reach these services via `localhost` regardless of the firewall — the open only matters for access from outside the host. Operators who want external reach now flip the bool explicitly: services.hyperhive.gateway.openFirewall = true; Each description updated to explain the new default + when to flip it (operator's browser, external git clients, federation announcement, etc.). Behind a host-level reverse proxy that handles TLS, leave off. Verified via `nix eval` on a clean stub config: - forge openFirewall = false - gateway openFirewall = false - matrix openFirewall = false - networking.firewall.allowedTCPPorts = [] (was: [80 2222 3000 8008]) Note: c0re's direct ports (7000/8000/8100-8999) are gated separately via #621 on `gateway.enable` — that gate stays; this PR only touches the per-module `openFirewall` knobs. Closes #651.
This commit is contained in:
parent
0b83e5a69e
commit
7feef4cc5d
3 changed files with 29 additions and 14 deletions
|
|
@ -87,12 +87,17 @@ in
|
|||
|
||||
openFirewall = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = true;
|
||||
default = false;
|
||||
example = true;
|
||||
description = ''
|
||||
Open `httpPort` + `sshPort` in the host firewall. Off when
|
||||
the forge should only be reachable from inside the host.
|
||||
(The container shares host netns, so this is the only
|
||||
firewall layer that matters.)
|
||||
Open `httpPort` + `sshPort` in the host firewall. Off by
|
||||
default (#651, secure-by-default): the forge is reachable
|
||||
from the host + every agent container via `localhost` either
|
||||
way (shared netns), so the firewall opens only matter for
|
||||
access from outside the host. Flip to `true` when you want
|
||||
the operator's browser / external git clients to hit the
|
||||
forge directly. (The container shares host netns, so this
|
||||
is the only firewall layer that matters.)
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
|
|
|||
Loading…
Reference in a new issue